| Legend | ||||||||||||||||
|
||||||||||||||||
1. Account associated with DEFAULT profile
2. Database Link Passwords in Cleartext
3. Default Accounts and Passwords
4. Default role password
5. Default SAP account
6. Excessive DBA Connections
7. Excessive Failed Logins
8. Expired password
9. Failed Login Attempts
10. Locked Accounts
11. OS Authentication Prefix
12. Overdue password change
13. Password Grace Time
14. Password Life Time
15. Password Lock Time
16. Password Reuse Max
17. Password Reuse Time
18. Password Verify Function
19. Remote Login Password File
20. Roles without passwords
21. Trusting Remote OS Authentication
22. Trusting Remote OS Roles
23. Unused or stale accounts
24. Users/Roles granted DBA privileges
25. Account can access source code as SYS
26. Account can become another user
27. Account can create public synonyms
28. Account can grant any role
29. Account can replace public links
30. Account granted ALTER SYSTEM privilege
31. Account granted the JAVA_ADMIN role
32. Account Permissions
33. Accounts with Default Tablespace SYS or SYSTEM
34. Audit Table Permissions
35. Create library privilege
36. Data Dictionary Accessibility
37. Database Link Permissions
38. List of ANY Permissions
39. Object Privileges granted directly to Users
40. Object Privileges Granted to PUBLIC
41. Privilege granted to SELECT from data dictionary
42. Privilege to execute DBMS_RANDOM granted to PUBLIC
43. Privilege to execute UTL_HTTP granted to PUBLIC
44. Privilege to execute UTL_SMTP granted to PUBLIC
45. Privilege to execute UTL_TCP granted to PUBLIC
46. Privileges granted with Admin
47. Privileges granted with Grant
48. Roles granted to PUBLIC
49. Roles granted with Admin
50. System Privileges granted directly to Users
51. System Privileges Granted to PUBLIC
52. Users granted the CONNECT role
53. Users granted the RESOURCE role
54. Listener password
55. Listener logging
56. Listener default name
57. Listener admin restrictions
58. Audit Table Tablespace
59. Audit Trail
60. Audit Trail Location
61. Auditing of CREATE SESSION not enabled
62. Composite Resource Usage Limit
63. Concurrent Sessions Resource Usage Limit
64. Connect Time Resource Usage Limit
65. CPU Per Call Resource Usage Limit
66. CPU Per Session Resource Usage Limit
67. Database Link Password Encryption
68. Idle Time Resource Usage Limit
69. Permissions on UTL_FILE package
70. Private SGA Resource Usage Limit
71. Reads Per Call Resource Usage Limit
72. Reads Per Session Resource Usage Limit
73. Resource Limits
74. SQL92 Security
75. Standard Password Verify Function Changed
76. SYS operations not audited
77. UTL_FILE_DIR Setting
78. Vulnerability Checks
| Authentication |
| Check : Database Link Passwords in Cleartext | ||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||
| Check : Default Accounts and Passwords | ||||||||||||||||||||||||||||||||||||||||||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||||||||||||||||||||||||||||||||||||||||||||
| Check : Default role password | ||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||
| Check : Default SAP account | ||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||
| Check : Excessive Failed Logins | ||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||
| Check : Expired password | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Check : Failed Login Attempts | ||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||||
| Check : Locked Accounts | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Check : OS Authentication Prefix | ||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||
| Check : Overdue password change | ||||||||||||||||||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||||||||||||||||||||
| Check : Password Grace Time | ||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||||
| Check : Password Life Time | ||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||||
| Check : Password Lock Time | ||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||||
| Check : Password Reuse Max | ||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||||
| Check : Password Reuse Time | ||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||||
| Check : Password Verify Function | ||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||
| Check : Remote Login Password File | ||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||||
| Check : Roles without passwords | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Check : Trusting Remote OS Authentication | ||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||||
| Check : Trusting Remote OS Roles | ||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||||
| Check : Users/Roles granted DBA privileges | |||||||||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
|||||||||||||||||
| Authorization |
| Check : Account can access source code as SYS | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Check : Account can become another user | ||||||||||||||||||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||||||||||||||||||||
| Check : Account can create public synonyms | ||||||||||||||||||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||||||||||||||||||||
| Check : Account can grant any role | ||||||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||||||||
| Check : Account can replace public links | |||||||||||||||||||||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
|||||||||||||||||||||||||||||
| Check : Account granted ALTER SYSTEM privilege | ||||||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||||||||
| Check : Account granted the JAVA_ADMIN role | ||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||
| Check : Accounts with Default Tablespace SYS or SYSTEM | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Check : Audit Table Permissions | ||||||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||||||||
| Check : Create library privilege | ||||||||||||||||||||||||||||||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||||||||||||||||||||||||||||||||
| Check : Data Dictionary Accessibility | ||||||||||
|
Description: CVE Reference No.: CVE-NO-MATCH
|
||||||||||